Описание
The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
Релиз | Статус | Примечание |
---|---|---|
devel | not-affected | |
hardy | not-affected | not the same software |
lucid | DNE | |
oneiric | not-affected | |
precise | not-affected | |
quantal | not-affected | |
upstream | not-affected |
Показывать по
Релиз | Статус | Примечание |
---|---|---|
devel | DNE | |
hardy | ignored | end of life |
lucid | not-affected | |
oneiric | DNE | |
precise | DNE | |
quantal | DNE | |
upstream | not-affected |
Показывать по
EPSS
4.3 Medium
CVSS2
Связанные уязвимости
The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
The imap-send command in GIT before 1.8.1.4 does not verify that the s ...
The imap-send command in GIT before 1.8.1.4 does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL servers via an arbitrary valid certificate.
EPSS
4.3 Medium
CVSS2